Maintenance for the week of April 6:
• ESO Store and Account System for maintenance – April 8, 9:00AM EDT (13:00 UTC) - 6:00PM EDT (22:00 UTC)
We are currently investigating connection issues some players are having on the European megaservers. We will update as new information becomes available.

Addon API Security Flaw: Bank is Accessible from Housing Storage Chests Using Addon API

Infinity_Knives
Infinity_Knives
Soul Shriven
RequestMoveItem Lua API call is successful between bank and inventory even though I am accessing a storage chest.
I assume this is unintended behavior as it is impossible to perform such an action in the vanilla UI.
Here is the addon that replicates such a bug: https://esoui.com/downloads/info430-CDGBankStacker.html
Even though this addon makes it easy to replicate this bug, I assume other addons could potentially exploit such a bug for even more broken interactions.

Steps to replicate:
  1. Install add-on from link above.
  2. Split a stack of a stackable item and deposit one stack into the bank.
  3. Go to housing and access storage chest.
  4. Observe successful stacking to bank from chat log and item count.

Here's a link to a video proving such an action is possible: https://youtu.be/X3TrDGdtjDE

EDIT:
Here's the ticket number for my in-game bug report submission: 200525-011665
Edited by Infinity_Knives on May 26, 2020 2:02AM
  • Dolgubon
    Dolgubon
    ✭✭✭✭
    Hey, i think I actually asked @ZOS_ChipHilseberg about this awhile ago. The answer I got was along the lines of 'it's not really exploitable so we'll leave it be'

    Note that it's additionally possible to withdraw items from storage as soon as you enter the house. Also in general, add-ons can do a lot of stuff that's not possible in the UI.
    Relthion: CP810 DK Tank - vMOL HM, vHOF HM, vAS HM, vCR +2
    Malorson: CP810 Mag Sorc - vMOL HM, vHOF, vAS HM

    Addons:
    Dolgubon's Lazy Writ Crafter
    Dolgubon's Lazy Set Crafter
  • Karm1cOne
    Karm1cOne
    ✭✭✭✭✭
    while i agree this is not an expected interaction, how would this be exploitable? it doesnt allow duplication, just quick movement between storage locations, and only in a home you own.
Sign In or Register to comment.